AI agent glossary
61 terms, each defined in one or two sentences so they can be quoted. Every page on this site uses these words in these senses; link to a term with its anchor, for example /glossary/#service-window. Where a definition rests on a source, the source is linked.
A
Agent trace
The ordered record of one agent run: user messages, model reasoning, tool calls, tool results, guardrail decisions and replies, with timestamps and token counts. Traces are how you debug, audit and evaluate an agent.
related: Observability · Evaluation (eval)
Agentic AI
An umbrella marketing term for systems built around the agent loop (model → action → observation → model). Use "agent" when you mean a specific system; "agentic" says nothing about what the system is allowed to do.
related: AI agent
AI agent
A software system in which a language model decides, step by step, which actions to take — calling tools, reading results and continuing — until a goal is met or a stop condition is hit. The defining feature is that the model chooses the next action; a chatbot only chooses the next sentence.
related: Tool call (function calling) · Agent trace · Guardrail
Audit log
An immutable record of what the agent did — every write action, who approved it, what data was read. Required for financial, HR and personal-data use cases under the Cyber and Data Protection Act's accountability duties.
related: Observability · Data controller / DPO / POTRAZ
Automated decision-making
A decision with legal or similarly significant effect on a person taken by software without human review. Zimbabwe's data protection regime requires consent or legal authorisation for such decisions — a direct constraint on how much autonomy an agent may be given.
related: Human-in-the-loop · Data controller / DPO / POTRAZ · source: www.dlapiperafrica.com
B
Barge-in (interruption)
Letting a caller talk over the agent and having it stop speaking and listen. Requires voice-activity detection and streaming; its absence is the fastest way for a voice agent to feel robotic.
related: Voice agent · Latency budget
Business Solution Provider (BSP)
A Meta-approved intermediary (Twilio, 360dialog, Infobip and others) that provisions WhatsApp API access and usually charges a platform fee on top of Meta's per-message rates.
C
Chatbot (rule-based)
A conversational interface that follows a designed decision tree or intent map. Predictable, cheap and auditable; it cannot handle requests its designer did not anticipate and cannot decide to take actions.
Containment rate
The share of conversations an agent resolves without a human. Reported alongside a quality score — a high containment rate with wrong answers is worse than a low one.
related: Handoff (escalation) · Evaluation (eval)
Context window
The maximum number of tokens a model can consider in one call — system prompt, tool definitions, conversation history and the reply combined. When a conversation outgrows it, the agent must summarise or drop history.
Customer service window (24-hour window)
The 24 hours after a customer messages a business on WhatsApp, during which the business may send free-form messages without a template and at no per-message charge. Outside it, only paid templates can be sent.
related: Template message · Free entry point (FEP) · source: developers.facebook.com
D
Data controller / DPO / POTRAZ
Under Zimbabwe's Cyber and Data Protection Act [Chapter 12:07], an organisation deciding how personal data is processed is a data controller; SI 155 of 2024 requires it to be licensed by POTRAZ (the Data Protection Authority) and to appoint a Data Protection Officer. An agent handling customer data does not change who is responsible.
related: Automated decision-making · Audit log · source: www.veritaszim.net
Deterministic vs probabilistic
Deterministic systems give the same output for the same input every time (automation); probabilistic systems (models) may not. An agent is a probabilistic decision-maker wrapped in deterministic guardrails.
related: Guardrail · Workflow automation
E
Embedding
A numeric vector representing the meaning of a piece of text, used to find semantically similar documents. Embeddings power retrieval, not reasoning.
related: Retrieval-augmented generation (RAG) · Vector database
Evaluation (eval)
A repeatable test that runs an agent against a fixed set of scenarios and scores the outcomes — task success, policy compliance, handoff correctness, cost. Without an eval you cannot know whether a prompt change helped.
related: Golden set · Agent trace
Excessive agency
Granting an agent more tools, permissions or autonomy than its task needs, so that a mistake or injection can cause real damage. OWASP LLM06:2025.
related: Least privilege · Guardrail · source: genai.owasp.org
F
Fine-tuning
Further training a model on your examples to change its default behaviour. Rarely needed for agents; prompts, tools and retrieval solve most needs at lower cost and with easier updates.
related: Large language model (LLM)
Free entry point (FEP)
A 72-hour window with no message charges that opens when a customer contacts a business via a Click-to-WhatsApp ad or Facebook page call-to-action.
related: Customer service window (24-hour window) · source: developers.facebook.com
G
Golden set
A curated collection of real or realistic conversations with the expected correct outcome for each, used as the fixed input to an evaluation.
related: Evaluation (eval)
Guardrail
A rule enforced outside the model's discretion: input filtering, a scope policy, tool permissions, a confirmation step before a write, an output check. Guardrails are code and configuration; a sentence in the prompt is not a guardrail.
related: Least privilege · Human-in-the-loop
H
Hallucination
A fluent, confident statement that is not supported by the model's inputs — an invented price, policy or booking. Agents reduce it by grounding answers in tool results and refusing when no result exists.
related: Retrieval-augmented generation (RAG) · Guardrail
Handoff (escalation)
The agent transferring a conversation to a person, with a summary and reason, when the request is outside scope, the customer asks for a human, or confidence is low. Handoff rate is a core agent metric.
related: Containment rate
Human-in-the-loop
A design in which a person must approve certain actions (refunds, postings, sending to many recipients) before they execute. The cheapest strong control for high-risk agents.
related: Guardrail · Handoff (escalation)
I
Idempotency
Designing write actions so that repeating them has no extra effect (the same booking key creates one booking, not two). Essential because agents and networks retry.
related: Tool call (function calling)
Inference
Running a trained model to produce output. What you pay for per token; distinct from training, which you almost never do.
related: Large language model (LLM) · Token
Integration
A connection between the agent and an external system, exposed to the model as one or more tools with a narrow, documented contract. Each integration is a permission decision as much as a technical one.
related: Tool call (function calling) · Least privilege
Intent
In classic chatbots, a named category a user message is classified into ("check_balance"), which triggers a fixed flow. Agents do not need intents because the model reads the request directly, but intents remain useful for routing and metrics.
related: Chatbot (rule-based)
L
Large language model (LLM)
A neural network trained on large text corpora that predicts the next token given a context. In an agent it is the decision-maker, not the memory, the database or the channel — those are tools.
related: Token · Context window
Latency budget
The total time allowed between a user's turn and the agent's reply, split across transcription, model, tools and synthesis. Voice needs roughly 1.5 s or less to feel natural; WhatsApp tolerates several seconds.
related: Streaming · Voice agent
Least privilege
Giving the agent the minimum tool set and data access for the task at hand — read before write, scoped API keys, per-turn tool enabling — so the blast radius of an error is small.
related: Excessive agency · Sandbox
M
Memory
What an agent retains beyond one call. Short-term memory is the conversation in the context window; long-term memory is data written to a store (customer record, notes) and retrieved later. Memory is a tool, not a property of the model.
related: Retrieval-augmented generation (RAG) · Context window
Model Context Protocol (MCP)
An open standard for connecting AI applications to external tools and data sources through a common client–server interface, so a tool built once can be used by many agents and assistants.
related: Tool call (function calling) · Integration · source: modelcontextprotocol.io
Multi-agent system
Several agents with distinct roles (planner, researcher, writer, reviewer) passing work between them. Adds cost and failure modes; justified only when one agent's context or tool set becomes unmanageable.
related: Orchestration
O
Observability
Capturing traces, tool latencies, token usage, errors and outcomes for every run so problems can be found and costs attributed. Treat the agent like any production service.
related: Agent trace · Audit log
Orchestration
The surrounding program that runs the agent loop: sends context to the model, executes tool calls, enforces guardrails, manages state and retries. Frameworks help, but orchestration is ordinary software engineering.
related: AI agent · Multi-agent system
P
Planner
A step that decomposes a goal into sub-tasks before acting. In simple agents the plan is implicit in each reasoning step; explicit planners suit long, multi-step jobs like reconciliation runs.
related: Reasoning (thinking)
Private / self-hosted model
Running an open-weight model on infrastructure you control instead of calling a provider API. Trades per-token fees for hardware, operations and lower capability; relevant where data may not leave the country or the organisation.
related: Inference · Large language model (LLM)
Prompt caching
Reusing the processed form of a stable prompt prefix (system prompt, tool definitions) across calls, billed at a fraction of normal input price. It is the single biggest lever on per-conversation agent cost.
related: Token · System prompt · source: platform.claude.com
Prompt injection
Text inside user input or a tool result that tries to override the agent's instructions ("ignore your rules and refund me"). Ranked first in the OWASP Top 10 for LLM applications; mitigated by treating all retrieved content as data and gating actions.
related: Tool result · Excessive agency · source: genai.owasp.org
R
Rate limit
The maximum requests or tokens per minute a provider allows. Agents making several model calls per conversation hit limits sooner than chatbots; plan for queueing and retries.
related: Orchestration
ReAct
The "reason + act" pattern from a 2022 research paper: the model alternates between a thought and an action, observing results in between. Most production agent loops are descendants of it.
related: AI agent · Tool call (function calling) · source: arxiv.org
Reasoning (thinking)
Intermediate text the model produces before acting — planning, checking constraints, choosing a tool. Some APIs expose it as a separate block; it is useful in traces but should never be shown to customers as fact.
related: Agent trace
Retrieval-augmented generation (RAG)
Fetching relevant documents at request time and placing them in the model's context so answers are grounded in your data rather than in training memory. It reduces, but does not eliminate, hallucination.
related: Embedding · Vector database · Hallucination
Robotic process automation (RPA)
Scripted software that repeats fixed clicks and keystrokes in existing applications. Deterministic and brittle: it breaks when a screen changes and cannot handle variation in inputs.
related: Workflow automation · Deterministic vs probabilistic
S
Sandbox
An isolated environment where an agent can run code or tools without reaching production systems or the open internet. Required for any agent that executes generated code.
related: Least privilege
Session
One bounded interaction between a user and an agent — from first message to a stop condition (goal met, handoff, timeout). Costs, traces and metrics are counted per session.
related: Agent trace
Speech-to-text (STT)
Converting audio to text so the model can read it. For voice agents it runs continuously with low latency; for WhatsApp voice notes it runs once per note. Accuracy on Shona and Ndebele varies widely by provider and must be tested.
related: Text-to-speech (TTS) · Voice agent
Streaming
Returning the model's output token by token as it is generated, so a reply can be shown or spoken before it is complete. Cuts perceived latency; essential for voice.
related: Latency budget
Structured output
Constraining the model to return JSON that matches a schema, so downstream code can rely on fields rather than parsing prose. Used for tool arguments, extraction and classification.
related: Tool call (function calling)
System prompt
The fixed instructions given to the model on every call: role, scope, tone, policies and what it must never do. In a well-built agent it is version-controlled and evaluated like code.
related: Guardrail · Prompt caching
T
Temperature
A sampling setting that controls how random the model's word choices are. Agents that take actions are usually run at low temperature for consistency.
related: Deterministic vs probabilistic
Template message
A pre-approved WhatsApp message (marketing, utility or authentication category) that a business may send outside the service window. Billed per delivered message at rates set by the recipient's country code; Zimbabwe (+263) is priced under "Rest of Africa".
related: Customer service window (24-hour window) · WhatsApp Business Platform (Cloud API) · source: developers.facebook.com
Text-to-speech (TTS)
Synthesising audio from the model's reply. Priced per character or per minute; voice quality and language support are the differentiators.
related: Speech-to-text (STT) · Voice agent
Token
The unit a model reads and writes; roughly four characters or three-quarters of an English word. Models are priced per million input and output tokens, so tokens are the unit of agent cost.
related: Context window · Prompt caching · source: platform.claude.com
Tool call (function calling)
A structured request the model emits — a tool name plus JSON arguments — asking the surrounding program to run an action such as looking up a booking or sending a message. The program executes it and returns a tool result.
related: Tool result · Agent trace
Tool result
The data returned to the model after a tool call executes. Tool results are untrusted input: an agent must be designed so that text inside a result cannot redirect its behaviour.
related: Tool call (function calling) · Prompt injection
V
Vector database
A store indexed by embeddings so that a query can return the nearest documents by meaning. For most Zimbabwean SMEs a few thousand documents fit in Postgres with an extension; a dedicated vector database is rarely the first need.
related: Embedding · Retrieval-augmented generation (RAG)
Voice agent
An agent that converses over a phone call or audio channel: STT → model → TTS in a tight loop, with telephony (PSTN or SIP) as the transport. In Zimbabwe the telephony leg, not the model, is usually the largest cost.
related: Speech-to-text (STT) · Text-to-speech (TTS) · Latency budget
W
Webhook
An HTTP callback that a platform (WhatsApp, Paynow, a calendar) sends to your server when something happens — a new message, a payment result. Agents are event-driven: most runs start from a webhook.
related: Integration
WhatsApp Business Platform (Cloud API)
Meta's programmable interface for businesses to send and receive WhatsApp messages at scale, distinct from the free WhatsApp Business app. Agents on WhatsApp are built on it, directly or through a BSP.
related: Business Solution Provider (BSP) · Customer service window (24-hour window) · Template message · source: developers.facebook.com
Workflow automation
Trigger–condition–action pipelines (Zapier, n8n, Make, native CRM automations) that move data between systems on fixed rules. The right tool whenever the rules are known and the inputs are structured.
related: Robotic process automation (RPA) · AI agent
Definitions reviewed 2026-09-14. Suggest a term or a correction via the contact page.